JSON Feed
Fetches indicators from a JSON feed.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedJSON
Configuration parameters
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- url — URL (required)
- auto_detect_type — Auto detect indicator type
- remove_ports — Remove IPv4 Ports
- indicator_type — Indicator Type
- credentials — Username
- extractor — JMESPath Extractor (required)
- indicator — JSON Indicator Attribute
- data — POST Data
- headers — Headers
- rawjson_include_indicator_type — Include indicator type for mapping
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- feedBypassExclusionList — Bypass exclusion list
- feedTags — Tags
- enrichmentExcluded — Enrichment Excluded
Commands (1)
- json-get-indicators — Gets the feed indicators.